· via TechCrunch
Asos confirms data breach after hackers used its own app to announce the compromise
Hackers calling themselves Xuanye Group hijacked Asos's app notifications to claim they had compromised its Snowflake-hosted data and threaten a leak; the retailer has now confirmed customer data was exposed.

A ransom note delivered through the app itself
Asos, the UK online fashion retailer, has confirmed that customer data was compromised after intruders broke in — and then used the company's own mobile app to tell customers about it.
According to TechCrunch, Asos disclosed the incident in a filing to the London Stock Exchange, saying the attackers had reached a third-party platform that hosts data the company uses to communicate with customers. Rather than quietly extorting the retailer, the group pushed a notification to shoppers' phones: a message addressed to Asos's data protection officer and IT department, claiming they had "fully compromised" the company's data held on Snowflake and warning, "Engage with us, or we will leak it."
SecurityWeek reported that the notification went out on the morning of 6 October at around 10:00 BST, with the text reported by the BBC. Screenshots spread quickly on social media. Charlotte Wilson of Check Point told the BBC the attackers had effectively turned Asos's app into their ransom note.
What was taken
Asos said names and contact information were affected, though the wording differs between reports: TechCrunch says the company described the data as taken, while SecurityWeek carried Asos's more cautious phrasing that the details "may have been accessed." BBC News reports the exposed information includes home addresses, phone numbers and email addresses, along with notes attached to customer profiles such as website search queries.
The company said it does not believe payment card details or account passwords were involved, according to SecurityWeek. The group behind the message, which calls itself the Xuanye Group, has not said how much data it holds, and cyber experts told the Guardian they had not encountered the group before.
The potential blast radius is large. Asos serves roughly 17 million customers a year across more than 150 markets, the BBC reported, and its shares fell by about a tenth on the day the news broke.
How the attackers got in
Two separate compromises appear to be involved. Bleeping Computer reports the intruders reached the Asos-run Snowflake instance by impersonating a trusted contact to obtain login credentials. Snowflake says it has found no breach of its own systems, though it told the BBC its investigation is still ongoing.
TechCrunch notes it remains unclear whether the Asos instance was protected with multi-factor authentication. It is also unknown how the attackers reached the push notification system, which is usually handled by another third-party service. Dan Bird of Horizon3 told the BBC that if both claims hold up, the credentials the attackers obtained opened more than one door. Malwarebytes added that Asos's marketing runs on Simon AI, a personalisation tool built on Snowflake whose customer profiles can cover purchase history, customer value and segments such as lapsed buyers.
A familiar pattern
The incident echoes the 2024 campaign against Snowflake customers. Mandiant, Google's incident-response arm, traced that wave to a group it tracks as UNC5537, which logged into customer accounts with credentials stolen by infostealer malware — some dating back as far as 2020 — and found no evidence that Snowflake's own environment had been breached. About 165 organisations were notified as potentially exposed. AT&T later disclosed that call and text records for nearly all of its cellular customers had been taken, and Wired reported the company paid a member of the hacking team roughly $370,000 to delete the data. Ticketmaster and Santander were linked to the same wave of attacks.
TechCrunch also points to a closer parallel from this year: fintech Betterment, whose third-party marketing platform was compromised and used to send a crypto scam to its customers, while names, email addresses and phone numbers were exposed.
Why it matters
The Asos breach shows how the most damaging access can be to infrastructure a company does not fully control. The attackers appear to have reached both a data warehouse and a communication channel, meaning the retailer's own app became the megaphone for an extortion attempt — pressuring Asos publicly in a way a private ransom demand would not. The 2024 Snowflake attacks already demonstrated that one stolen warehouse credential can expose years of records on millions of people, and key questions here — MFA on the warehouse account, access to the notification pipeline — remain unanswered. Until they are, Asos customers should assume their contact details are exposed and expect phishing that already knows their name, address and shopping habits.
- #security
- #data-breach
- #retail
- #snowflake
- #mobile-apps